Microsoft Defender flags legitimate Google search links as malicious

A widespread issue has been uncovered in Microsoft’s security software, where legitimate Google search links are being mistakenly flagged as malicious by Defender for Office 365. The problem affects users who see “Opening this website might not be safe” warnings when trying to access blocked hyperlinks. This is not a minor glitch – the impact could be significant, given the widespread use of Microsoft’s security solutions in organizations.

According to an internal service alert obtained by BleepingComputer, the issue stems from an inaccurate security classification. When users try to access these links directly in their browser, they are still blocked by Defender for Office 365’s Safe Links feature. The company has acknowledged the incident and is working on a solution to correct the misclassification.

Microsoft’s Safe Links feature is designed to protect against phishing attacks and other malicious activities by rewriting inbound email messages during mail flow and performing time-of-click verification of URLs in email messages, Teams, and Office 365 apps. However, in this case, it appears that the system has become overzealous in its security checks, mistakenly identifying legitimate links as malicious.

The issue is not limited to individual users – IT administrators may also see alerts in Microsoft Sentinel’s SIEM solution and the Defender portal regarding this ongoing incident. The company has classified it as an advisory, which typically describes service issues involving a limited scope or impact. However, the actual number of affected customers and regions remains unknown.

This is not the first time that Microsoft has faced criticism for its security software producing false positives. Last year, an Exchange Online bug caused machine learning models to mistakenly flag emails from Gmail accounts as spam. Another issue resulted in anti-spam systems quarantining legitimate emails. More recently, a widespread Microsoft 365 outage led to authentication issues and service delays.

Given the importance of security solutions like Defender for Office 365, this incident serves as a reminder that even the most well-intentioned systems can have flaws. For users who are affected by this issue, there is little they can do except wait for Microsoft’s solution. However, IT administrators may want to review their security configurations and consider implementing additional safeguards to prevent similar issues in the future.

One practical takeaway from this incident is that even legitimate links can be incorrectly flagged as malicious by advanced security systems. This highlights the need for organizations to regularly review and update their security policies and procedures to ensure they are not inadvertently blocking legitimate traffic. By taking proactive steps, businesses can minimize the risk of being caught off guard by unexpected issues like this one.


Source: Bleeping Computer — 2026-09-02